[389-users] access control

Rich Megginson rmeggins at redhat.com
Mon Oct 25 22:42:59 UTC 2010


Anthony Messina wrote:
> On Monday, October 25, 2010 03:14:59 am Morris, Patrick wrote:
>   
>> http://directory.fedoraproject.org/wiki/Howto:AccessControl
>>
>> On 10/23/2010 6:38 PM, Mike Li wrote:
>>     
>>> I am using the latest 389 DS (1.1), on Linux. Searching the entries 
>>> works but cannot do add/modify, ldap_add_s() and ldap_modify_s() APIs 
>>> return: Insufficient access.
>>>
>>> How do I give the write access to a login (identified by a login DN 
>>> and passwd) ? Searched everywhere but cannot find any help at all.
>>>
>>> Thanks.
>>>       
>
> Anyone know how to set ACIs for connections using the socket interface?
>
> I see we can restrict to IP address or hostname/domain, but I don't see 
> anything for SLAPI.  Thanks in advance.  -A
>   
I think you mean LDAPI.  There is nothing explicit - however, you can 
set access based on hostname or IP address.  I suppose, since an LDAPI 
connection has no hostname or IP address, you might be able to use that 
somehow.
> ------------------------------------------------------------------------
>
> --
> 389 users mailing list
> 389-users at lists.fedoraproject.org
> https://admin.fedoraproject.org/mailman/listinfo/389-users




More information about the 389-users mailing list